First published: Wed Nov 01 2023(Updated: )
The response messages received from the eSOMS report generation using certain parameter queries with full file path can be abused for enumerating the local file system structure.
Credit: cybersecurity@hitachienergy.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hitachienergy Esoms | <=6.3.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the eSOMS report generation vulnerability is CVE-2023-5514.
The severity of CVE-2023-5514 is medium with a CVSS score of 5.3.
The eSOMS report generation vulnerability allows the enumeration of the local file system structure through certain parameter queries with full file path in the response messages.
Hitachienergy Esoms version 6.3.13 is affected by CVE-2023-5514.
More information about CVE-2023-5514 can be found at https://publisher.hitachienergy.com/preview?DocumentId=8DBD000175&languageCode=en&Preview=true.